CVE-2025-68168: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: jfs: fix uninitialized waitqueue in transaction manager The transaction manager initialization in txInit() was not properly initializing TxBlock[0].waitor waitqueue, causing a crash when txEnd(0) is called on read-only filesystems. When a filesystem is mounted read-only, txBegin() returns tid=0 to indicate no transaction. However, txEnd(0) still gets called and tries to access TxBlock[0].waitor via tid_to_tblock(0), but this waitqueue was never initialized because the initialization loop started at index 1 instead of 0. This causes a 'non-static key' lockdep warning and system crash: INFO: trying to register non-static key in txEnd Fix by ensuring all transaction blocks including TxBlock[0] have their waitqueues properly initialized during txInit().

Affected products

  • Linux Linux: from 5.4.255, before 5.4.302 (fixed in 5.4.302); from 5.10.192, before 5.10.247 (fixed in 5.10.247); from 5.15.123, before 5.15.197 (fixed in 5.15.197); from 6.1.42, before 6.1.159 (fixed in 6.1.159); from 4.14.324, before 4.15 (fixed in 4.15); from 4.19.293, before 4.20 (fixed in 4.20); …

Published 2025-12-16. Last modified 2026-07-30.